← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

CISA Retires Weekly Vulnerability Bulletin, Shifts to Risk-Based Approach

🔄 Updated 6d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CISA's weekly vulnerability bulletin will be retired September 28.
  • The bulletin summarized thousands of new vulnerabilities weekly.
  • CISA is moving to a risk-based vulnerability management approach.
  • This aligns with Binding Operational Directive (BOD) 26-04.

Bulletin Discontinuation

The US Cybersecurity and Infrastructure Security Agency (CISA) announced the retirement of its weekly vulnerability bulletin, effective September 28. This bulletin provided a summary of new vulnerabilities recorded each week, including product names, descriptions, publication dates, severity, CVSS scores, CVE identifiers, and patch information when available.

Shift to Risk-Based Management

The discontinuation is part of CISA's pivot to a risk-based approach in vulnerability management. The previous bulletin, while comprehensive, listed thousands of vulnerabilities without specific guidance on prioritization, potentially leading to alert fatigue for defenders due to the sheer volume of flaws.

This move aligns with Binding Operational Directive (BOD) 26-04, which instructs federal agencies to prioritize vulnerabilities based on real-world risk factors, including evidence of exploitation and exposure, rather than relying solely on severity scores.

Industry Trend and KEV Catalog

The broader cybersecurity industry has been transitioning away from sole reliance on CVSS metrics, which measure theoretical technical severity. Modern risk-based frameworks prioritize active exploits, threat actor interest, and exposure levels.

CISA's Known Exploited Vulnerabilities (KEV) catalog, introduced in 2021, has become a primary reference point for defenders. The KEV list focuses strictly on bugs with documented in-the-wild exploitation, offering actionable prioritization that static weekly bulletins could not provide.

Future Vulnerability Information

Security operations centers (SOCs) that previously relied on the weekly bulletin for new vulnerability information may need to adjust their processes. CISA stated it will continue to provide risk-focused vulnerability information through its KEV catalog, alerts, and advisories.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The US Cybersecurity and Infrastructure Security Agency (CISA) is discontinuing its weekly vulnerability bulletin on September 28. This change aligns with a broader shift towards prioritizing vulnerabilities based on real-world risk factors, such as active exploitation, rather than solely on severity scores.